
Summer means vacations, travel, and working from some pretty unconventional locations - cafés, airports, hotel rooms, beaches with a hotspot. Unfortunately, that same relaxed atmosphere is exactly what attackers are counting on. Distracted, tired, and slightly off their usual routine, even careful people cut corners they wouldn't cut at their desk. And that's precisely the window attackers are looking for.
Here's what deserves your attention when work travels with you.
Free Wi-Fi at the airport or hotel is tempting, but these networks are frequently unsecured or poorly configured, and attackers can intercept traffic or set up a rogue access point with a name close enough to fool you at a glance. Easy as "Hotel_Guest_WiFi_Free" instead of "Hotel_GuestWiFi." Before connecting, confirm the exact network name with staff, and use a VPN for any work-related traffic without exception. No VPN available? Use mobile data or your own hotspot instead - a few extra megabytes cost less than a compromised account.
A laptop or phone left on a café table while you grab your coffee is all it takes for someone to walk off with it in seconds. And they will. Unattended devices in transit hubs are a known target of opportunity, not a hypothetical. Keep devices with you at all times, or lock them in the hotel safe, never in an unattended room without supervision, and never left visible inside a parked car. Lock your screen even when you step away for a moment, especially in shared spaces and busy work areas where a "moment" is all anyone needs.
Working on sensitive documents on a plane or train means the person next to you can read your screen just as easily as you can. If you must work while in transit, use a privacy screen filter, and where possible avoid accessing sensitive systems (HR data, financials, contracts) until you're somewhere more private. It's a low-effort habit that closes a surprisingly common gap.
Public USB charging stations at airports can be compromised to deliver malware through the data pins of the charging cable - the same cable that's supposed to just top up your battery. Bring your own charger with a wall outlet, or use a power bank. If a public USB port is genuinely your only option, use a USB data blocker adapter, which passes power through but blocks the data connection.
Travel is exactly when credentials are most likely to be exposed. A shoulder-surfed password, a session hijacked over a spoofed hotspot, a phished login page that looked convincing enough at 6 a.m. before a flight. Multi-factor authentication doesn't prevent every mistake, but it's the layer that turns a stolen password into a dead end rather than a breach. Before you travel, confirm your MFA method actually works away from your usual setup, an authenticator app that depends on push notifications, for instance, needs a working data connection, so make sure you have a backup method (like a one-time code) that doesn't.
Every summer brings a spike in fake emails about "an issue with your flight booking," "your accommodation has been cancelled," or "a gate change" - perfect opportunities for phishing. This is all classic bait acting as seasonal urgency. Check the sender address, don't click on suspicious links, and verify any booking directly on the official website rather than through a link in an email. If it's urgent enough to threaten cancelling your trip, it's urgent enough to verify through a second channel.
Report a lost or stolen work device, a suspected account compromise, or a phishing attempt during travel to your InfoSec team or IT support as soon as possible, even if you're not sure the incident is real. A false alarm costs a few minutes of someone's time; a delayed report can cost a lot more. A fast response, account lockout, remote wipe, is usually what separates a minor inconvenience from a serious security incident.
A few minutes of setup now means you actually get to disconnect later. Have a good trip.